Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Prosím o kontrolu logu

Příspěvekod Holecek » 15 lis 2013 18:38

Při spuštění hlásí, že acevents.exe nelze spustit

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:34:32, on 15.11.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16736)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\windows\system32\taskmgr.exe
C:\TOTALCMD\TOTALCMD.EXE
E:\Programy\Údržba\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - Startup: AutorunsDisabled
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: AuthenTec Fingerprint Service (ATService) - AuthenTec, Inc. - C:\Program Files\Fingerprint Sensor\AtService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 9159 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 15 lis 2013 21:30

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Holecek » 15 lis 2013 22:37

# AdwCleaner v3.012 - Report created 15/11/2013 at 22:16:47
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : KATKA - KATKA-PC
# Running from : C:\Users\KATKA\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-1.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-10.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-11.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-12.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-13.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-14.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-15.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-2.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-3.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-4.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-5.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-6.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-7.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-8.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-9.xml
File Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\user.js
Folder Found : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Found : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Found C:\Program Files\Conduit
Folder Found C:\Program Files\ICQ6Toolbar
Folder Found C:\ProgramData\AlawarWrapper
Folder Found C:\ProgramData\Ask
Folder Found C:\ProgramData\ICQ\ICQToolbar
Folder Found C:\Users\KATKA\AppData\LocalLow\Conduit
Folder Found C:\Users\KATKA\AppData\LocalLow\PriceGong
Folder Found C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\ICQToolbarData

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\smartbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Found : HKLM\Software\ICQ\ICQToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16736

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd

-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\prefs.js ]

Line Found : user_pref("CT3220468.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.seznam.cz%2F\",\"EB_MAIN_FRAME_TITLE\":\"Seznam%20%E2%80%93%20Najdu%20tam%2C%20co%20nezn%C3%A1m\"}");
Line Found : user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1384544900674,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Found : user_pref("browser.search.defaultengine", "Ask.com");
Line Found : user_pref("browser.search.order.1", "Ask.com");
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Found : user_pref("smartBar.searchInNewTabOwner", "CT3220468");
Line Found : user_pref("smartbar.machineId", "37RFPDXJGMIU+BMOVSSGFR7PREB1MNAWYIB7EYSJC5/TJOLL8CODSUXUJJMA1+/PHXX/UI4X6++MKX6TP2YKUA");

-\\ Google Chrome v30.0.1599.101

[ File : C:\Users\KATKA\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found : icon_url
Found : search_url
Found : suggest_url
Found : keyword
Found : search_url
Found : suggest_url

*************************

AdwCleaner[R0].txt - [6532 octets] - [15/11/2013 22:16:47]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6592 octets] ##########


Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.11.15.09

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16736
KATKA :: KATKA-PC [administrátor]

15.11.2013 22:22:29
mbam-log-2013-11-15 (22-22-29).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 211176
Uplynulý čas: 13 minut, 45 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 16 lis 2013 08:56

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat-Clean
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Holecek » 16 lis 2013 13:27

# AdwCleaner v3.012 - Report created 16/11/2013 at 12:54:12
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : KATKA - KATKA-PC
# Running from : E:\Programy\Údržba\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\ICQ6Toolbar
Folder Deleted : C:\Users\KATKA\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\KATKA\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\ICQToolbarData
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-10.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-11.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-12.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-13.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-14.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-15.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-7.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-8.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\searchplugins\icqplugin-9.xml
File Deleted : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\smartbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\ICQ\ICQToolbar

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16736

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\prefs.js ]

Line Deleted : user_pref("CT3220468.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.seznam.cz%2F\",\"EB_MAIN_FRAME_TITLE\":\"Seznam%20%E2%80%93%20Najdu%20tam%2C%20co%20nezn%C3%A1m\"}");
Line Deleted : user_pref("CT3220468_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1384544900674,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("smartBar.searchInNewTabOwner", "CT3220468");
Line Deleted : user_pref("smartbar.machineId", "37RFPDXJGMIU+BMOVSSGFR7PREB1MNAWYIB7EYSJC5/TJOLL8CODSUXUJJMA1+/PHXX/UI4X6++MKX6TP2YKUA");

-\\ Google Chrome v30.0.1599.101

[ File : C:\Users\KATKA\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword

*************************

AdwCleaner[R0].txt - [6672 octets] - [15/11/2013 22:16:47]
AdwCleaner[R1].txt - [6477 octets] - [16/11/2013 12:53:01]
AdwCleaner[S0].txt - [6427 octets] - [16/11/2013 12:54:12]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6487 octets] ##########


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x86
Ran by KATKA on so 16.11.2013 at 13:04:34,15
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{41787657-08EF-454B-B25B-8474825CC2D4}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{570B161C-316F-4B2B-9B5F-E2B44E1A18F0}



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\KATKA\AppData\Roaming\mozilla\firefox\profiles\phy63bx8.default\minidumps [122 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 16.11.2013 at 13:11:23,42
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : KATKA [Práva správce]
Mód : Kontrola -- Datum : 11/16/2013 13:22:18
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP UNIC][DLL] explorer.exe -- E:\Programy\Údržba\SUPERAntiSpywarePortable\App\SUPERAntiSpyware\SASCTXMN.DLL [x] -> ODEBRÁNO

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS723232L9A360 +++++
--- User ---
[MBR] 5dd89b5edef27f5fa2becb310eba704b
[BSP] b3a04b8d3f6327ed3989a30734aa1718 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 287535 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 589488128 | Size: 15360 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 620945408 | Size: 2043 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Corsair Flash Voyager USB Device +++++
--- User ---
[MBR] 0a24d2a2546ed5bfa4d3a5229cffd6b4
[BSP] 33a07a59d299ab4ea9f4ab0156f9d86f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0x0b) [VISIBLE] Offset (sectors): 32 | Size: 3839 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[0]_S_11162013_132218.txt >>

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Holecek » 16 lis 2013 13:50

Výstřižek.JPG

Toto po každém spuštění notebooku vyskakuje, ale nepřišel jsem na to, který program by se měl přeinstalovat. Je to počítač dětí a nevím co s ním vyváděli.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 17 lis 2013 10:06

http://www.processlibrary.com/en/direct ... ts/242828/

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller


Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Holecek » 17 lis 2013 11:37

RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : KATKA [Práva správce]
Mód : Odebrat -- Datum : 11/17/2013 10:56:37
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP UNIC][DLL] explorer.exe -- E:\Programy\Údržba\SUPERAntiSpywarePortable\App\SUPERAntiSpyware\SASCTXMN.DLL [x] -> ODEBRÁNO

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS723232L9A360 +++++
--- User ---
[MBR] 5dd89b5edef27f5fa2becb310eba704b
[BSP] b3a04b8d3f6327ed3989a30734aa1718 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 287535 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 589488128 | Size: 15360 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 620945408 | Size: 2043 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_11172013_105637.txt >>
RKreport[0]_S_11162013_132218.txt;RKreport[0]_S_11172013_105034.txt



11:26:20.0971 5468 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:26:28.0756 5468 ============================================================
11:26:28.0756 5468 Current date / time: 2013/11/17 11:26:28.0756
11:26:28.0756 5468 SystemInfo:
11:26:28.0756 5468
11:26:28.0756 5468 OS Version: 6.1.7601 ServicePack: 1.0
11:26:28.0756 5468 Product type: Workstation
11:26:28.0756 5468 ComputerName: KATKA-PC
11:26:28.0756 5468 UserName: KATKA
11:26:28.0756 5468 Windows directory: C:\windows
11:26:28.0756 5468 System windows directory: C:\windows
11:26:28.0756 5468 Processor architecture: Intel x86
11:26:28.0756 5468 Number of processors: 2
11:26:28.0756 5468 Page size: 0x1000
11:26:28.0756 5468 Boot type: Normal boot
11:26:28.0756 5468 ============================================================
11:26:29.0676 5468 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:26:29.0676 5468 ============================================================
11:26:29.0676 5468 \Device\Harddisk0\DR0:
11:26:29.0676 5468 MBR partitions:
11:26:29.0676 5468 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x96000
11:26:29.0676 5468 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x96800, BlocksNum 0x23197800
11:26:29.0676 5468 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x2322E000, BlocksNum 0x1E00000
11:26:29.0676 5468 \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x2502E000, BlocksNum 0x3FD800
11:26:29.0676 5468 ============================================================
11:26:29.0707 5468 C: <-> \Device\Harddisk0\DR0\Partition2
11:26:29.0739 5468 E: <-> \Device\Harddisk0\DR0\Partition4
11:26:29.0739 5468 ============================================================
11:26:29.0739 5468 Initialize success
11:26:29.0739 5468 ============================================================
11:26:37.0835 5684 ============================================================
11:26:37.0835 5684 Scan started
11:26:37.0835 5684 Mode: Manual;
11:26:37.0835 5684 ============================================================
11:26:38.0116 5684 ================ Scan system memory ========================
11:26:38.0116 5684 System memory - ok
11:26:38.0131 5684 ================ Scan services =============================
11:26:38.0397 5684 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
11:26:38.0397 5684 1394ohci - ok
11:26:38.0459 5684 [ 080A40550FB95A328917512F3F5A0409 ] 5U876UVC C:\windows\system32\DRIVERS\5U876.sys
11:26:38.0459 5684 5U876UVC - ok
11:26:38.0553 5684 [ 00659E56339389469473AEC41587E706 ] ac.sharedstore C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
11:26:38.0553 5684 ac.sharedstore - ok
11:26:38.0615 5684 [ 4DF5E6215A102A192B2B6DBB61F2FBA5 ] Accelerometer C:\windows\system32\DRIVERS\Accelerometer.sys
11:26:38.0615 5684 Accelerometer - ok
11:26:38.0662 5684 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\windows\system32\drivers\ACPI.sys
11:26:38.0677 5684 ACPI - ok
11:26:38.0709 5684 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
11:26:38.0724 5684 AcpiPmi - ok
11:26:38.0787 5684 [ 6C61BCEB60C2C187E6F96001FD69493E ] ADIHdAudAddService C:\windows\system32\drivers\ADIHdAud.sys
11:26:38.0802 5684 ADIHdAudAddService - ok
11:26:38.0911 5684 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
11:26:38.0911 5684 AdobeARMservice - ok
11:26:39.0036 5684 [ 438F31336B3DC248ABC632F1C8F34A24 ] AdobeFlashPlayerUpdateSvc C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:26:39.0036 5684 AdobeFlashPlayerUpdateSvc - ok
11:26:39.0099 5684 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\windows\system32\DRIVERS\adp94xx.sys
11:26:39.0114 5684 adp94xx - ok
11:26:39.0161 5684 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\windows\system32\DRIVERS\adpahci.sys
11:26:39.0161 5684 adpahci - ok
11:26:39.0192 5684 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\windows\system32\DRIVERS\adpu320.sys
11:26:39.0192 5684 adpu320 - ok
11:26:39.0239 5684 [ 4DC6B0772D1698F04FC79053A21C8260 ] AEADIFilters C:\windows\system32\AEADISRV.EXE
11:26:39.0239 5684 AEADIFilters - ok
11:26:39.0270 5684 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
11:26:39.0270 5684 AeLookupSvc - ok
11:26:39.0348 5684 [ F81BB7E487EDCEAB630A7EE66CF23913 ] AFD C:\windows\system32\drivers\afd.sys
11:26:39.0364 5684 AFD - ok
11:26:39.0426 5684 [ 7E10E3BB9B258AD8A9300F91214D67B9 ] AgereSoftModem C:\windows\system32\DRIVERS\AGRSM.sys
11:26:39.0442 5684 AgereSoftModem - ok
11:26:39.0489 5684 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\windows\system32\drivers\agp440.sys
11:26:39.0489 5684 agp440 - ok
11:26:39.0551 5684 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\windows\system32\DRIVERS\djsvs.sys
11:26:39.0551 5684 aic78xx - ok
11:26:39.0613 5684 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\windows\System32\alg.exe
11:26:39.0613 5684 ALG - ok
11:26:39.0676 5684 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\windows\system32\drivers\aliide.sys
11:26:39.0676 5684 aliide - ok
11:26:39.0707 5684 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\windows\system32\drivers\amdagp.sys
11:26:39.0707 5684 amdagp - ok
11:26:39.0738 5684 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\windows\system32\drivers\amdide.sys
11:26:39.0738 5684 amdide - ok
11:26:39.0785 5684 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\windows\system32\DRIVERS\amdk8.sys
11:26:39.0785 5684 AmdK8 - ok
11:26:39.0816 5684 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\windows\system32\DRIVERS\amdppm.sys
11:26:39.0816 5684 AmdPPM - ok
11:26:39.0879 5684 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\windows\system32\drivers\amdsata.sys
11:26:39.0879 5684 amdsata - ok
11:26:39.0926 5684 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\windows\system32\DRIVERS\amdsbs.sys
11:26:39.0926 5684 amdsbs - ok
11:26:39.0957 5684 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\windows\system32\drivers\amdxata.sys
11:26:39.0957 5684 amdxata - ok
11:26:40.0019 5684 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\windows\system32\drivers\appid.sys
11:26:40.0019 5684 AppID - ok
11:26:40.0035 5684 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\windows\System32\appidsvc.dll
11:26:40.0035 5684 AppIDSvc - ok
11:26:40.0097 5684 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\windows\System32\appinfo.dll
11:26:40.0097 5684 Appinfo - ok
11:26:40.0128 5684 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\windows\system32\DRIVERS\arc.sys
11:26:40.0128 5684 arc - ok
11:26:40.0144 5684 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\windows\system32\DRIVERS\arcsas.sys
11:26:40.0144 5684 arcsas - ok
11:26:40.0222 5684 [ 37B781DF6F1AE6FB4A419F42CDF30CC3 ] ASBroker C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
11:26:40.0238 5684 ASBroker - ok
11:26:40.0253 5684 [ 1AEE23BA023CDA7909B9AD1CEF21764F ] ASChannel C:\Program Files\Hewlett-Packard\IAM\Bin\AsChnl.dll
11:26:40.0253 5684 ASChannel - ok
11:26:40.0284 5684 [ B9FE438B3CAD82B2014710349A2022F7 ] aswFsBlk C:\windows\system32\drivers\aswFsBlk.sys
11:26:40.0284 5684 aswFsBlk - ok
11:26:40.0378 5684 [ D58AC76EB4D2B478B654EBD6550965BB ] aswKbd C:\windows\system32\drivers\aswKbd.sys
11:26:40.0378 5684 aswKbd - ok
11:26:40.0425 5684 [ AE5549DD21F6DE06406031EF1D51ACC3 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
11:26:40.0440 5684 aswMonFlt - ok
11:26:40.0503 5684 [ A29EF1A46E110F392588F7395BB55F32 ] aswRdr C:\windows\System32\Drivers\aswrdr2.sys
11:26:40.0503 5684 aswRdr - ok
11:26:40.0565 5684 [ FA72FA503F580C3C628DD8C7D7622E37 ] aswRvrt C:\windows\system32\drivers\aswRvrt.sys
11:26:40.0565 5684 aswRvrt - ok
11:26:40.0628 5684 [ 4D53349D848C6BADB3D4ACBE98C27676 ] aswSnx C:\windows\system32\drivers\aswSnx.sys
11:26:40.0643 5684 aswSnx - ok
11:26:40.0706 5684 [ 813024DFD54A41B3AFAE2B1E2796CB80 ] aswSP C:\windows\system32\drivers\aswSP.sys
11:26:40.0721 5684 aswSP - ok
11:26:40.0737 5684 [ 5E18413310134130D7772F0668698CB7 ] aswTdi C:\windows\system32\drivers\aswTdi.sys
11:26:40.0737 5684 aswTdi - ok
11:26:40.0768 5684 [ A5F637D61719D37A5B4868C385E363C0 ] aswVmm C:\windows\system32\drivers\aswVmm.sys
11:26:40.0768 5684 aswVmm - ok
11:26:40.0784 5684 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
11:26:40.0799 5684 AsyncMac - ok
11:26:40.0846 5684 [ 338C86357871C167A96AB976519BF59E ] atapi C:\windows\system32\drivers\atapi.sys
11:26:40.0862 5684 atapi - ok
11:26:41.0049 5684 [ 712D8A95E45B070114C5309ADA7358FF ] atikmdag C:\windows\system32\drivers\atikmdag.sys
11:26:41.0127 5684 atikmdag - ok
11:26:41.0236 5684 [ B09D413EB812F65651162C516C75CC5F ] ATService C:\Program Files\Fingerprint Sensor\AtService.exe
11:26:41.0252 5684 ATService - ok
11:26:41.0314 5684 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
11:26:41.0330 5684 AudioEndpointBuilder - ok
11:26:41.0361 5684 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\windows\System32\Audiosrv.dll
11:26:41.0361 5684 Audiosrv - ok
11:26:41.0439 5684 [ 9330941C8F6DF417F6DBBE998DB6687E ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
11:26:41.0439 5684 avast! Antivirus - ok
11:26:41.0486 5684 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\windows\System32\AxInstSV.dll
11:26:41.0486 5684 AxInstSV - ok
11:26:41.0548 5684 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\windows\system32\DRIVERS\bxvbdx.sys
11:26:41.0564 5684 b06bdrv - ok
11:26:41.0610 5684 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
11:26:41.0626 5684 b57nd60x - ok
11:26:41.0766 5684 [ B9E94D37FC08525D893B632A0CA2E18C ] BCM43XX C:\windows\system32\DRIVERS\bcmwl6.sys
11:26:41.0798 5684 BCM43XX - ok
11:26:41.0829 5684 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\windows\System32\bdesvc.dll
11:26:41.0844 5684 BDESVC - ok
11:26:41.0876 5684 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\windows\system32\drivers\Beep.sys
11:26:41.0891 5684 Beep - ok
11:26:41.0954 5684 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\windows\System32\bfe.dll
11:26:41.0969 5684 BFE - ok
11:26:42.0016 5684 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\windows\System32\qmgr.dll
11:26:42.0032 5684 BITS - ok
11:26:42.0078 5684 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
11:26:42.0078 5684 blbdrive - ok
11:26:42.0110 5684 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\windows\system32\DRIVERS\bowser.sys
11:26:42.0110 5684 bowser - ok
11:26:42.0125 5684 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\DRIVERS\BrFiltLo.sys
11:26:42.0141 5684 BrFiltLo - ok
11:26:42.0156 5684 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\DRIVERS\BrFiltUp.sys
11:26:42.0156 5684 BrFiltUp - ok
11:26:42.0203 5684 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\windows\System32\browser.dll
11:26:42.0203 5684 Browser - ok
11:26:42.0234 5684 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\windows\System32\Drivers\Brserid.sys
11:26:42.0250 5684 Brserid - ok
11:26:42.0266 5684 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
11:26:42.0266 5684 BrSerWdm - ok
11:26:42.0297 5684 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
11:26:42.0297 5684 BrUsbMdm - ok
11:26:42.0312 5684 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
11:26:42.0312 5684 BrUsbSer - ok
11:26:42.0375 5684 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\windows\system32\drivers\BthEnum.sys
11:26:42.0375 5684 BthEnum - ok
11:26:42.0390 5684 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\windows\system32\DRIVERS\bthmodem.sys
11:26:42.0406 5684 BTHMODEM - ok
11:26:42.0453 5684 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
11:26:42.0453 5684 BthPan - ok
11:26:42.0500 5684 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
11:26:42.0515 5684 BTHPORT - ok
11:26:42.0578 5684 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\windows\system32\bthserv.dll
11:26:42.0578 5684 bthserv - ok
11:26:42.0609 5684 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
11:26:42.0609 5684 BTHUSB - ok
11:26:42.0656 5684 [ D57D29132EFE13A83133D9BD449E0CF1 ] btwaudio C:\windows\system32\drivers\btwaudio.sys
11:26:42.0671 5684 btwaudio - ok
11:26:42.0718 5684 [ D282C14A69357D0E1BAFAECC2CA98C3A ] btwavdt C:\windows\system32\drivers\btwavdt.sys
11:26:42.0718 5684 btwavdt - ok
11:26:42.0796 5684 [ 7D2DD14E60CE4FF3308D66FDA7990546 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
11:26:42.0812 5684 btwdins - ok
11:26:42.0827 5684 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\windows\system32\DRIVERS\btwl2cap.sys
11:26:42.0827 5684 btwl2cap - ok
11:26:42.0858 5684 [ 02EB4D2B05967DF2D32F29C84AB1FB17 ] btwrchid C:\windows\system32\DRIVERS\btwrchid.sys
11:26:42.0874 5684 btwrchid - ok
11:26:42.0921 5684 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
11:26:42.0921 5684 cdfs - ok
11:26:42.0983 5684 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\windows\system32\drivers\cdrom.sys
11:26:42.0983 5684 cdrom - ok
11:26:43.0046 5684 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\windows\System32\certprop.dll
11:26:43.0046 5684 CertPropSvc - ok
11:26:43.0077 5684 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\windows\system32\DRIVERS\circlass.sys
11:26:43.0077 5684 circlass - ok
11:26:43.0108 5684 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\windows\system32\CLFS.sys
11:26:43.0124 5684 CLFS - ok
11:26:43.0186 5684 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:26:43.0202 5684 clr_optimization_v2.0.50727_32 - ok
11:26:43.0295 5684 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:26:43.0326 5684 clr_optimization_v4.0.30319_32 - ok
11:26:43.0358 5684 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
11:26:43.0358 5684 CmBatt - ok
11:26:43.0389 5684 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\windows\system32\drivers\cmdide.sys
11:26:43.0389 5684 cmdide - ok
11:26:43.0451 5684 [ 85449EEBE8F8EBD6481EFBF0F352B4EB ] CNG C:\windows\system32\Drivers\cng.sys
11:26:43.0451 5684 CNG - ok
11:26:43.0545 5684 [ F9A79C5B27037821112C50A9C8FB367A ] Com4QLBEx C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
11:26:43.0545 5684 Com4QLBEx - ok
11:26:43.0560 5684 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\windows\system32\DRIVERS\compbatt.sys
11:26:43.0560 5684 Compbatt - ok
11:26:43.0638 5684 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys
11:26:43.0638 5684 CompositeBus - ok
11:26:43.0670 5684 COMSysApp - ok
11:26:43.0701 5684 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\windows\system32\DRIVERS\crcdisk.sys
11:26:43.0701 5684 crcdisk - ok
11:26:43.0779 5684 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\windows\system32\cryptsvc.dll
11:26:43.0779 5684 CryptSvc - ok
11:26:43.0826 5684 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\windows\system32\rpcss.dll
11:26:43.0841 5684 DcomLaunch - ok
11:26:43.0872 5684 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\windows\System32\defragsvc.dll
11:26:43.0888 5684 defragsvc - ok
11:26:43.0919 5684 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\windows\system32\Drivers\dfsc.sys
11:26:43.0919 5684 DfsC - ok
11:26:43.0982 5684 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\windows\system32\dhcpcore.dll
11:26:43.0997 5684 Dhcp - ok
11:26:44.0028 5684 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\windows\system32\drivers\discache.sys
11:26:44.0028 5684 discache - ok
11:26:44.0106 5684 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\windows\system32\DRIVERS\disk.sys
11:26:44.0106 5684 Disk - ok
11:26:44.0138 5684 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\windows\System32\dnsrslvr.dll
11:26:44.0138 5684 Dnscache - ok
11:26:44.0169 5684 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\windows\System32\dot3svc.dll
11:26:44.0169 5684 dot3svc - ok
11:26:44.0216 5684 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\windows\system32\dps.dll
11:26:44.0216 5684 DPS - ok
11:26:44.0262 5684 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
11:26:44.0278 5684 drmkaud - ok
11:26:44.0340 5684 [ 71BC35067CABC02C9453AEAA42B2E43E ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
11:26:44.0340 5684 DXGKrnl - ok
11:26:44.0387 5684 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\windows\System32\eapsvc.dll
11:26:44.0387 5684 EapHost - ok
11:26:44.0528 5684 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\windows\system32\DRIVERS\evbdx.sys
11:26:44.0574 5684 ebdrv - ok
11:26:44.0621 5684 [ 803B370865D907EA21DC0C2B6A8936B5 ] EFS C:\windows\System32\lsass.exe
11:26:44.0637 5684 EFS - ok
11:26:44.0699 5684 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\windows\ehome\ehRecvr.exe
11:26:44.0715 5684 ehRecvr - ok
11:26:44.0746 5684 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\windows\ehome\ehsched.exe
11:26:44.0746 5684 ehSched - ok
11:26:44.0808 5684 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\windows\system32\DRIVERS\elxstor.sys
11:26:44.0824 5684 elxstor - ok
11:26:44.0871 5684 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\windows\system32\drivers\errdev.sys
11:26:44.0871 5684 ErrDev - ok
11:26:44.0949 5684 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\windows\system32\es.dll
11:26:44.0949 5684 EventSystem - ok
11:26:44.0996 5684 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\windows\system32\drivers\exfat.sys
11:26:44.0996 5684 exfat - ok
11:26:45.0027 5684 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\windows\system32\drivers\fastfat.sys
11:26:45.0027 5684 fastfat - ok
11:26:45.0105 5684 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\windows\system32\fxssvc.exe
11:26:45.0120 5684 Fax - ok
11:26:45.0152 5684 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\windows\system32\DRIVERS\fdc.sys
11:26:45.0152 5684 fdc - ok
11:26:45.0183 5684 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\windows\system32\fdPHost.dll
11:26:45.0183 5684 fdPHost - ok
11:26:45.0198 5684 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\windows\system32\fdrespub.dll
11:26:45.0214 5684 FDResPub - ok
11:26:45.0230 5684 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
11:26:45.0230 5684 FileInfo - ok
11:26:45.0245 5684 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\windows\system32\drivers\filetrace.sys
11:26:45.0245 5684 Filetrace - ok
11:26:45.0276 5684 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\windows\system32\DRIVERS\flpydisk.sys
11:26:45.0276 5684 flpydisk - ok
11:26:45.0323 5684 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
11:26:45.0323 5684 FltMgr - ok
11:26:45.0417 5684 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\windows\system32\FntCache.dll
11:26:45.0432 5684 FontCache - ok
11:26:45.0495 5684 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:26:45.0495 5684 FontCache3.0.0.0 - ok
11:26:45.0526 5684 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\windows\system32\drivers\FsDepends.sys
11:26:45.0542 5684 FsDepends - ok
11:26:45.0573 5684 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
11:26:45.0573 5684 Fs_Rec - ok
11:26:45.0635 5684 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
11:26:45.0651 5684 fvevol - ok
11:26:45.0698 5684 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\windows\system32\DRIVERS\gagp30kx.sys
11:26:45.0713 5684 gagp30kx - ok
11:26:45.0744 5684 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\windows\System32\gpsvc.dll
11:26:45.0776 5684 gpsvc - ok
11:26:45.0854 5684 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
11:26:45.0854 5684 gupdate - ok
11:26:45.0869 5684 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
11:26:45.0869 5684 gupdatem - ok
11:26:45.0900 5684 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
11:26:45.0900 5684 hcw85cir - ok
11:26:45.0963 5684 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
11:26:45.0963 5684 HdAudAddService - ok
11:26:46.0010 5684 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys
11:26:46.0010 5684 HDAudBus - ok
11:26:46.0041 5684 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\windows\system32\DRIVERS\HidBatt.sys
11:26:46.0041 5684 HidBatt - ok
11:26:46.0056 5684 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\windows\system32\DRIVERS\hidbth.sys
11:26:46.0056 5684 HidBth - ok
11:26:46.0119 5684 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\windows\system32\DRIVERS\hidir.sys
11:26:46.0119 5684 HidIr - ok
11:26:46.0150 5684 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\windows\system32\hidserv.dll
11:26:46.0150 5684 hidserv - ok
11:26:46.0181 5684 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
11:26:46.0181 5684 HidUsb - ok
11:26:46.0228 5684 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\windows\system32\kmsvc.dll
11:26:46.0228 5684 hkmsvc - ok
11:26:46.0275 5684 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\windows\system32\ListSvc.dll
11:26:46.0275 5684 HomeGroupListener - ok
11:26:46.0290 5684 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\windows\system32\provsvc.dll
11:26:46.0306 5684 HomeGroupProvider - ok
11:26:46.0368 5684 [ 9FF8868DE43435DF5F015CA7D786C3E2 ] HP ProtectTools Service C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
11:26:46.0384 5684 HP ProtectTools Service - ok
11:26:46.0462 5684 [ 13BB1114451C63BFB41BA7DAA4D70A29 ] HP Support Assistant Service C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
11:26:46.0462 5684 HP Support Assistant Service - ok
11:26:46.0540 5684 [ BCC4A8B2E2E902F52E7F2E7D8E125765 ] HPDrvMntSvc.exe C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
11:26:46.0540 5684 HPDrvMntSvc.exe - ok
11:26:46.0556 5684 [ E1D82F0C8456ABB03B7DF5D623CA47D1 ] hpdskflt C:\windows\system32\DRIVERS\hpdskflt.sys
11:26:46.0556 5684 hpdskflt - ok
11:26:46.0602 5684 [ 4A4A85248DDBA176257913D53FFF393E ] HpFkCryptService C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
11:26:46.0618 5684 HpFkCryptService - ok
11:26:46.0680 5684 [ 1210960FF8928950D2A786895B0C424A ] HpqKbFiltr C:\windows\system32\DRIVERS\HpqKbFiltr.sys
11:26:46.0680 5684 HpqKbFiltr - ok
11:26:46.0774 5684 [ EC9739A46F1F83C6E52A7A4697F44A65 ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
11:26:46.0774 5684 hpqwmiex - ok
11:26:46.0836 5684 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
11:26:46.0852 5684 HpSAMD - ok
11:26:46.0852 5684 [ D1F817E61D52816996B8F1EBA9A38276 ] hpsrv C:\windows\system32\Hpservice.exe
11:26:46.0868 5684 hpsrv - ok
11:26:46.0930 5684 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\windows\system32\drivers\HTTP.sys
11:26:46.0946 5684 HTTP - ok
11:26:46.0961 5684 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
11:26:46.0961 5684 hwpolicy - ok
11:26:47.0008 5684 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\windows\system32\drivers\i8042prt.sys
11:26:47.0008 5684 i8042prt - ok
11:26:47.0102 5684 [ F54B3DB096ABD6E9BBBD052FD3878A48 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
11:26:47.0102 5684 IAANTMON - ok
11:26:47.0164 5684 [ 01446278D4563B3013C92830AE6CBB26 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys
11:26:47.0180 5684 iaStor - ok
11:26:47.0211 5684 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\windows\system32\drivers\iaStorV.sys
11:26:47.0211 5684 iaStorV - ok
11:26:47.0289 5684 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
11:26:47.0304 5684 IDriverT - ok
11:26:47.0367 5684 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:26:47.0382 5684 idsvc - ok
11:26:47.0632 5684 [ A70C995199A47F326EEF4F9F5E6267A1 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
11:26:47.0741 5684 igfx - ok
11:26:47.0804 5684 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\windows\system32\DRIVERS\iirsp.sys
11:26:47.0804 5684 iirsp - ok
11:26:47.0882 5684 [ B9C54120F46392100478F58F374E5709 ] IKEEXT C:\windows\System32\ikeext.dll
11:26:47.0913 5684 IKEEXT - ok
11:26:47.0991 5684 [ E63CD0D9AA8D406CABDE5AA718936F40 ] IntcHdmiAddService C:\windows\system32\drivers\IntcHdmi.sys
11:26:47.0991 5684 IntcHdmiAddService - ok
11:26:48.0006 5684 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\windows\system32\drivers\intelide.sys
11:26:48.0022 5684 intelide - ok
11:26:48.0069 5684 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
11:26:48.0069 5684 intelppm - ok
11:26:48.0100 5684 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\windows\system32\ipbusenum.dll
11:26:48.0116 5684 IPBusEnum - ok
11:26:48.0147 5684 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
11:26:48.0147 5684 IpFilterDriver - ok
11:26:48.0194 5684 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\windows\System32\iphlpsvc.dll
11:26:48.0209 5684 iphlpsvc - ok
11:26:48.0256 5684 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
11:26:48.0256 5684 IPMIDRV - ok
11:26:48.0287 5684 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\windows\system32\drivers\ipnat.sys
11:26:48.0287 5684 IPNAT - ok
11:26:48.0334 5684 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\windows\system32\drivers\irenum.sys
11:26:48.0350 5684 IRENUM - ok
11:26:48.0350 5684 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\windows\system32\drivers\isapnp.sys
11:26:48.0365 5684 isapnp - ok
11:26:48.0381 5684 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
11:26:48.0396 5684 iScsiPrt - ok
11:26:48.0474 5684 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\windows\system32\drivers\kbdclass.sys
11:26:48.0474 5684 kbdclass - ok
11:26:48.0506 5684 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\windows\system32\drivers\kbdhid.sys
11:26:48.0506 5684 kbdhid - ok
11:26:48.0537 5684 [ 803B370865D907EA21DC0C2B6A8936B5 ] KeyIso C:\windows\system32\lsass.exe
11:26:48.0552 5684 KeyIso - ok
11:26:48.0584 5684 [ F286830298323272260332D6ABC905C1 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
11:26:48.0599 5684 KSecDD - ok
11:26:48.0615 5684 [ D7C760D57B1656DD748B9E4AB6CB5A51 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
11:26:48.0615 5684 KSecPkg - ok
11:26:48.0677 5684 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\windows\system32\msdtckrm.dll
11:26:48.0693 5684 KtmRm - ok
11:26:48.0755 5684 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\windows\system32\srvsvc.dll
11:26:48.0771 5684 LanmanServer - ok
11:26:48.0833 5684 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
11:26:48.0849 5684 LanmanWorkstation - ok
11:26:48.0927 5684 [ 83D8BE94E1CBCBE2EA8372DB1A95A159 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
11:26:48.0927 5684 LightScribeService - ok
11:26:48.0989 5684 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
11:26:48.0989 5684 lltdio - ok
11:26:49.0020 5684 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\windows\System32\lltdsvc.dll
11:26:49.0036 5684 lltdsvc - ok
11:26:49.0052 5684 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\windows\System32\lmhsvc.dll
11:26:49.0067 5684 lmhosts - ok
11:26:49.0130 5684 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\windows\system32\DRIVERS\lsi_fc.sys
11:26:49.0130 5684 LSI_FC - ok
11:26:49.0176 5684 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\windows\system32\DRIVERS\lsi_sas.sys
11:26:49.0176 5684 LSI_SAS - ok
11:26:49.0192 5684 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\windows\system32\DRIVERS\lsi_sas2.sys
11:26:49.0192 5684 LSI_SAS2 - ok
11:26:49.0223 5684 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\windows\system32\DRIVERS\lsi_scsi.sys
11:26:49.0223 5684 LSI_SCSI - ok
11:26:49.0270 5684 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\windows\system32\drivers\luafv.sys
11:26:49.0270 5684 luafv - ok
11:26:49.0348 5684 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\windows\system32\drivers\mbam.sys
11:26:49.0348 5684 MBAMProtector - ok
11:26:49.0442 5684 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
11:26:49.0457 5684 MBAMScheduler - ok
11:26:49.0535 5684 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
11:26:49.0551 5684 MBAMService - ok
11:26:49.0613 5684 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
11:26:49.0613 5684 Mcx2Svc - ok
11:26:49.0644 5684 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\windows\system32\DRIVERS\megasas.sys
11:26:49.0644 5684 megasas - ok
11:26:49.0691 5684 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\windows\system32\DRIVERS\MegaSR.sys
11:26:49.0707 5684 MegaSR - ok
11:26:49.0769 5684 [ 64B96DE8C492BD435372D9130A535F1D ] MfeAVFK C:\windows\system32\drivers\MfeAVFK.sys
11:26:49.0769 5684 MfeAVFK - ok
11:26:49.0785 5684 [ 078E87A89D36CC3516F19D5FB518BDDC ] MfeBOPK C:\windows\system32\drivers\MfeBOPK.sys
11:26:49.0785 5684 MfeBOPK - ok
11:26:49.0832 5684 [ 168C565101FD5B9DB694EFDEC91FAFA9 ] mfehidk C:\windows\system32\drivers\mfehidk.sys
11:26:49.0832 5684 mfehidk - ok
11:26:49.0863 5684 [ E0842F67DC9BC4D21D1E319610EBE9E5 ] MfeRKDK C:\windows\system32\drivers\MfeRKDK.sys
11:26:49.0863 5684 MfeRKDK - ok
11:26:49.0910 5684 [ 43A7ACBBD70ECD62F0B63486C72089A3 ] mfetdik C:\windows\system32\drivers\mfetdik.sys
11:26:49.0910 5684 mfetdik - ok
11:26:49.0941 5684 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\windows\system32\mmcss.dll
11:26:49.0941 5684 MMCSS - ok
11:26:49.0988 5684 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\windows\system32\drivers\modem.sys
11:26:49.0988 5684 Modem - ok
11:26:50.0034 5684 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\windows\system32\DRIVERS\monitor.sys
11:26:50.0034 5684 monitor - ok
11:26:50.0081 5684 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
11:26:50.0081 5684 mouclass - ok
11:26:50.0128 5684 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
11:26:50.0144 5684 mouhid - ok
11:26:50.0159 5684 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\windows\system32\drivers\mountmgr.sys
11:26:50.0175 5684 mountmgr - ok
11:26:50.0268 5684 [ 5E0686615A80A6279B2314E13CD23F6E ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:26:50.0268 5684 MozillaMaintenance - ok
11:26:50.0300 5684 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\windows\system32\drivers\mpio.sys
11:26:50.0315 5684 mpio - ok
11:26:50.0331 5684 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
11:26:50.0331 5684 mpsdrv - ok
11:26:50.0378 5684 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\windows\system32\mpssvc.dll
11:26:50.0409 5684 MpsSvc - ok
11:26:50.0456 5684 [ 21F4B24ACFC79A483515BD986DD9043F ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
11:26:50.0456 5684 MRxDAV - ok
11:26:50.0502 5684 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
11:26:50.0502 5684 mrxsmb - ok
11:26:50.0549 5684 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
11:26:50.0549 5684 mrxsmb10 - ok
11:26:50.0580 5684 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
11:26:50.0580 5684 mrxsmb20 - ok
11:26:50.0612 5684 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\windows\system32\drivers\msahci.sys
11:26:50.0612 5684 msahci - ok
11:26:50.0658 5684 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\windows\system32\drivers\msdsm.sys
11:26:50.0658 5684 msdsm - ok
11:26:50.0690 5684 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\windows\System32\msdtc.exe
11:26:50.0705 5684 MSDTC - ok
11:26:50.0768 5684 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\windows\system32\drivers\Msfs.sys
11:26:50.0768 5684 Msfs - ok
11:26:50.0783 5684 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
11:26:50.0783 5684 mshidkmdf - ok
11:26:50.0814 5684 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
11:26:50.0830 5684 msisadrv - ok
11:26:50.0861 5684 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\windows\system32\iscsiexe.dll
11:26:50.0861 5684 MSiSCSI - ok
11:26:50.0877 5684 msiserver - ok
11:26:50.0924 5684 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
11:26:50.0924 5684 MSKSSRV - ok
11:26:50.0939 5684 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
11:26:50.0955 5684 MSPCLOCK - ok
11:26:50.0970 5684 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
11:26:50.0970 5684 MSPQM - ok
11:26:50.0986 5684 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
11:26:51.0002 5684 MsRPC - ok
11:26:51.0017 5684 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\windows\system32\drivers\mssmbios.sys
11:26:51.0033 5684 mssmbios - ok
11:26:51.0048 5684 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
11:26:51.0048 5684 MSTEE - ok
11:26:51.0064 5684 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\windows\system32\DRIVERS\MTConfig.sys
11:26:51.0064 5684 MTConfig - ok
11:26:51.0080 5684 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\windows\system32\Drivers\mup.sys
11:26:51.0095 5684 Mup - ok
11:26:51.0126 5684 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\windows\system32\qagentRT.dll
11:26:51.0142 5684 napagent - ok
11:26:51.0204 5684 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
11:26:51.0204 5684 NativeWifiP - ok
11:26:51.0282 5684 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\windows\system32\drivers\ndis.sys
11:26:51.0298 5684 NDIS - ok
11:26:51.0329 5684 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
11:26:51.0329 5684 NdisCap - ok
11:26:51.0376 5684 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
11:26:51.0376 5684 NdisTapi - ok
11:26:51.0438 5684 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
11:26:51.0438 5684 Ndisuio - ok
11:26:51.0470 5684 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
11:26:51.0470 5684 NdisWan - ok
11:26:51.0501 5684 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
11:26:51.0501 5684 NDProxy - ok
11:26:51.0548 5684 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
11:26:51.0548 5684 NetBIOS - ok
11:26:51.0579 5684 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
11:26:51.0579 5684 NetBT - ok
11:26:51.0610 5684 [ 803B370865D907EA21DC0C2B6A8936B5 ] Netlogon C:\windows\system32\lsass.exe
11:26:51.0610 5684 Netlogon - ok
11:26:51.0672 5684 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\windows\System32\netman.dll
11:26:51.0688 5684 Netman - ok
11:26:51.0719 5684 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\windows\System32\netprofm.dll
11:26:51.0719 5684 netprofm - ok
11:26:51.0766 5684 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:26:51.0766 5684 NetTcpPortSharing - ok
11:26:51.0922 5684 [ 58218EC6B61B1169CF54AAB0D00F5FE2 ] netw5v32 C:\windows\system32\DRIVERS\netw5v32.sys
11:26:51.0984 5684 netw5v32 - ok
11:26:52.0078 5684 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\windows\system32\DRIVERS\nfrd960.sys
11:26:52.0094 5684 nfrd960 - ok
11:26:52.0125 5684 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\windows\System32\nlasvc.dll
11:26:52.0140 5684 NlaSvc - ok
11:26:52.0218 5684 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\windows\system32\drivers\ccdcmb.sys
11:26:52.0218 5684 nmwcd - ok
11:26:52.0250 5684 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\windows\system32\drivers\ccdcmbo.sys
11:26:52.0250 5684 nmwcdc - ok
11:26:52.0281 5684 [ 99B224F8026CB534724AA3C408561E45 ] nmwcdnsu C:\windows\system32\drivers\nmwcdnsu.sys
11:26:52.0296 5684 nmwcdnsu - ok
11:26:52.0343 5684 [ D23257682D349A5E2E4507ED33DECC16 ] nmwcdnsuc C:\windows\system32\drivers\nmwcdnsuc.sys
11:26:52.0359 5684 nmwcdnsuc - ok
11:26:52.0390 5684 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\windows\system32\drivers\Npfs.sys
11:26:52.0390 5684 Npfs - ok
11:26:52.0421 5684 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\windows\system32\nsisvc.dll
11:26:52.0421 5684 nsi - ok
11:26:52.0437 5684 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
11:26:52.0437 5684 nsiproxy - ok
11:26:52.0530 5684 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\windows\system32\drivers\Ntfs.sys
11:26:52.0546 5684 Ntfs - ok
11:26:52.0577 5684 [ F9756A98D69098DCA8945D62858A812C ] Null C:\windows\system32\drivers\Null.sys
11:26:52.0577 5684 Null - ok
11:26:52.0608 5684 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\windows\system32\drivers\nvraid.sys
11:26:52.0608 5684 nvraid - ok
11:26:52.0640 5684 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\windows\system32\drivers\nvstor.sys
11:26:52.0640 5684 nvstor - ok
11:26:52.0686 5684 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\windows\system32\drivers\nv_agp.sys
11:26:52.0686 5684 nv_agp - ok
11:26:52.0780 5684 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:26:52.0796 5684 odserv - ok
11:26:52.0827 5684 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
11:26:52.0827 5684 ohci1394 - ok
11:26:52.0858 5684 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:26:52.0874 5684 ose - ok
11:26:52.0936 5684 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\windows\system32\pnrpsvc.dll
11:26:52.0952 5684 p2pimsvc - ok
11:26:53.0014 5684 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\windows\system32\p2psvc.dll
11:26:53.0030 5684 p2psvc - ok
11:26:53.0092 5684 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\windows\system32\DRIVERS\parport.sys
11:26:53.0092 5684 Parport - ok
11:26:53.0139 5684 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\windows\system32\drivers\partmgr.sys
11:26:53.0139 5684 partmgr - ok
11:26:53.0154 5684 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\windows\system32\DRIVERS\parvdm.sys
11:26:53.0154 5684 Parvdm - ok
11:26:53.0186 5684 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\windows\System32\pcasvc.dll
11:26:53.0201 5684 PcaSvc - ok
11:26:53.0264 5684 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\windows\system32\DRIVERS\pccsmcfd.sys
11:26:53.0279 5684 pccsmcfd - ok
11:26:53.0310 5684 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\windows\system32\drivers\pci.sys
11:26:53.0310 5684 pci - ok
11:26:53.0357 5684 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\windows\system32\drivers\pciide.sys
11:26:53.0357 5684 pciide - ok
11:26:53.0373 5684 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\windows\system32\DRIVERS\pcmcia.sys
11:26:53.0388 5684 pcmcia - ok
11:26:53.0451 5684 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\windows\system32\drivers\pcw.sys
11:26:53.0451 5684 pcw - ok
11:26:53.0482 5684 pdfcDispatcher - ok
11:26:53.0560 5684 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\windows\system32\drivers\peauth.sys
11:26:53.0576 5684 PEAUTH - ok
11:26:53.0669 5684 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\windows\system32\pla.dll
11:26:53.0716 5684 pla - ok
11:26:53.0794 5684 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\windows\system32\umpnpmgr.dll
11:26:53.0810 5684 PlugPlay - ok
11:26:53.0825 5684 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
11:26:53.0841 5684 PNRPAutoReg - ok
11:26:53.0872 5684 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\windows\system32\pnrpsvc.dll
11:26:53.0888 5684 PNRPsvc - ok
11:26:53.0934 5684 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\windows\System32\ipsecsvc.dll
11:26:53.0950 5684 PolicyAgent - ok
11:26:53.0997 5684 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\windows\system32\umpo.dll
11:26:54.0012 5684 Power - ok
11:26:54.0075 5684 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
11:26:54.0075 5684 PptpMiniport - ok
11:26:54.0090 5684 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\windows\system32\DRIVERS\processr.sys
11:26:54.0106 5684 Processor - ok
11:26:54.0168 5684 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\windows\system32\profsvc.dll
11:26:54.0184 5684 ProfSvc - ok
11:26:54.0215 5684 [ 803B370865D907EA21DC0C2B6A8936B5 ] ProtectedStorage C:\windows\system32\lsass.exe
11:26:54.0231 5684 ProtectedStorage - ok
11:26:54.0262 5684 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\windows\system32\DRIVERS\pacer.sys
11:26:54.0278 5684 Psched - ok
11:26:54.0293 5684 [ 40FEDD328F98245AD201CF5F9F311724 ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
11:26:54.0309 5684 PxHelp20 - ok
11:26:54.0371 5684 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\windows\system32\DRIVERS\ql2300.sys
11:26:54.0387 5684 ql2300 - ok
11:26:54.0418 5684 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\windows\system32\DRIVERS\ql40xx.sys
11:26:54.0418 5684 ql40xx - ok
11:26:54.0465 5684 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\windows\system32\qwave.dll
11:26:54.0480 5684 QWAVE - ok
11:26:54.0496 5684 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
11:26:54.0512 5684 QWAVEdrv - ok
11:26:54.0527 5684 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
11:26:54.0543 5684 RasAcd - ok
11:26:54.0590 5684 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
11:26:54.0590 5684 RasAgileVpn - ok
11:26:54.0605 5684 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\windows\System32\rasauto.dll
11:26:54.0621 5684 RasAuto - ok
11:26:54.0636 5684 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
11:26:54.0636 5684 Rasl2tp - ok
11:26:54.0699 5684 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\windows\System32\rasmans.dll
11:26:54.0714 5684 RasMan - ok
11:26:54.0730 5684 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
11:26:54.0730 5684 RasPppoe - ok
11:26:54.0746 5684 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
11:26:54.0761 5684 RasSstp - ok
11:26:54.0777 5684 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
11:26:54.0792 5684 rdbss - ok
11:26:54.0824 5684 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\windows\system32\DRIVERS\rdpbus.sys
11:26:54.0824 5684 rdpbus - ok
11:26:54.0870 5684 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
11:26:54.0870 5684 RDPCDD - ok
11:26:54.0917 5684 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
11:26:54.0917 5684 RDPENCDD - ok
11:26:54.0933 5684 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
11:26:54.0948 5684 RDPREFMP - ok
11:26:54.0980 5684 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
11:26:54.0995 5684 RDPWD - ok

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Holecek » 17 lis 2013 11:38

11:26:55.0011 5684 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
11:26:55.0026 5684 rdyboost - ok
11:26:55.0058 5684 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\windows\System32\mprdim.dll
11:26:55.0058 5684 RemoteAccess - ok
11:26:55.0089 5684 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\windows\system32\regsvc.dll
11:26:55.0104 5684 RemoteRegistry - ok
11:26:55.0167 5684 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\windows\system32\DRIVERS\rfcomm.sys
11:26:55.0167 5684 RFCOMM - ok
11:26:55.0276 5684 [ 85F9924FB26D924C4A10DC620AE2C350 ] RoxMediaDB10 c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
11:26:55.0323 5684 RoxMediaDB10 - ok
11:26:55.0370 5684 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
11:26:55.0385 5684 RpcEptMapper - ok
11:26:55.0416 5684 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\windows\system32\locator.exe
11:26:55.0416 5684 RpcLocator - ok
11:26:55.0463 5684 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\windows\system32\rpcss.dll
11:26:55.0479 5684 RpcSs - ok
11:26:55.0526 5684 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
11:26:55.0541 5684 rspndr - ok
11:26:55.0588 5684 [ 13335D083935AB88E09C9ACC077355B5 ] RsvLock C:\windows\system32\drivers\RsvLock.sys
11:26:55.0588 5684 RsvLock - ok
11:26:55.0650 5684 [ 062B82FA74C895382AB0784D493C8C9C ] SafeBoot C:\windows\system32\drivers\SafeBoot.sys
11:26:55.0650 5684 Suspicious file (NoAccess): C:\windows\system32\drivers\SafeBoot.sys. md5: 062B82FA74C895382AB0784D493C8C9C
11:26:55.0650 5684 SafeBoot ( LockedFile.Multi.Generic ) - warning
11:26:55.0650 5684 SafeBoot - detected LockedFile.Multi.Generic (1)
11:26:55.0682 5684 [ 803B370865D907EA21DC0C2B6A8936B5 ] SamSs C:\windows\system32\lsass.exe
11:26:55.0682 5684 SamSs - ok
11:26:55.0713 5684 [ C9CB2C392C35CBEE2733C836D23DC642 ] SbAlg C:\windows\system32\drivers\SbAlg.sys
11:26:55.0713 5684 SbAlg - ok
11:26:55.0760 5684 [ B5A8ECDEE930B52FD3BA35700A15EA53 ] SbFsLock C:\windows\system32\drivers\SbFsLock.sys
11:26:55.0760 5684 SbFsLock - ok
11:26:55.0822 5684 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\windows\system32\drivers\sbp2port.sys
11:26:55.0822 5684 sbp2port - ok
11:26:55.0853 5684 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\windows\System32\SCardSvr.dll
11:26:55.0869 5684 SCardSvr - ok
11:26:55.0900 5684 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
11:26:55.0916 5684 scfilter - ok
11:26:55.0978 5684 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\windows\system32\schedsvc.dll
11:26:56.0009 5684 Schedule - ok
11:26:56.0025 5684 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\windows\System32\certprop.dll
11:26:56.0025 5684 SCPolicySvc - ok
11:26:56.0087 5684 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\windows\System32\SDRSVC.dll
11:26:56.0087 5684 SDRSVC - ok
11:26:56.0150 5684 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
11:26:56.0150 5684 secdrv - ok
11:26:56.0165 5684 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\windows\system32\seclogon.dll
11:26:56.0181 5684 seclogon - ok
11:26:56.0228 5684 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\windows\System32\sens.dll
11:26:56.0243 5684 SENS - ok
11:26:56.0274 5684 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\windows\system32\sensrsvc.dll
11:26:56.0290 5684 SensrSvc - ok
11:26:56.0321 5684 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\windows\system32\DRIVERS\serenum.sys
11:26:56.0321 5684 Serenum - ok
11:26:56.0337 5684 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\windows\system32\DRIVERS\serial.sys
11:26:56.0337 5684 Serial - ok
11:26:56.0384 5684 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\windows\system32\DRIVERS\sermouse.sys
11:26:56.0384 5684 sermouse - ok
11:26:56.0477 5684 [ F31E9531AF225CA25350D5E87E999B31 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
11:26:56.0493 5684 ServiceLayer - ok
11:26:56.0555 5684 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\windows\system32\sessenv.dll
11:26:56.0571 5684 SessionEnv - ok
11:26:56.0602 5684 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\windows\system32\drivers\sffdisk.sys
11:26:56.0602 5684 sffdisk - ok
11:26:56.0618 5684 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
11:26:56.0618 5684 sffp_mmc - ok
11:26:56.0633 5684 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
11:26:56.0633 5684 sffp_sd - ok
11:26:56.0664 5684 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\windows\system32\DRIVERS\sfloppy.sys
11:26:56.0664 5684 sfloppy - ok
11:26:56.0696 5684 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\windows\System32\ipnathlp.dll
11:26:56.0711 5684 SharedAccess - ok
11:26:56.0758 5684 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\windows\System32\shsvcs.dll
11:26:56.0789 5684 ShellHWDetection - ok
11:26:56.0805 5684 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\windows\system32\drivers\sisagp.sys
11:26:56.0805 5684 sisagp - ok
11:26:56.0852 5684 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\windows\system32\DRIVERS\SiSRaid2.sys
11:26:56.0852 5684 SiSRaid2 - ok
11:26:56.0867 5684 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\windows\system32\DRIVERS\sisraid4.sys
11:26:56.0883 5684 SiSRaid4 - ok
11:26:57.0101 5684 [ 9F712B26EE3B0242DE997A42FD302E2C ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
11:26:57.0164 5684 Skype C2C Service - ok
11:26:57.0304 5684 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
11:26:57.0304 5684 SkypeUpdate - ok
11:26:57.0366 5684 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\windows\system32\DRIVERS\smb.sys
11:26:57.0366 5684 Smb - ok
11:26:57.0444 5684 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\windows\System32\snmptrap.exe
11:26:57.0460 5684 SNMPTRAP - ok
11:26:57.0476 5684 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\windows\system32\drivers\spldr.sys
11:26:57.0476 5684 spldr - ok
11:26:57.0522 5684 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\windows\System32\spoolsv.exe
11:26:57.0554 5684 Spooler - ok
11:26:57.0678 5684 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\windows\system32\sppsvc.exe
11:26:57.0741 5684 sppsvc - ok
11:26:57.0772 5684 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\windows\system32\sppuinotify.dll
11:26:57.0772 5684 sppuinotify - ok
11:26:57.0803 5684 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\windows\system32\DRIVERS\srv.sys
11:26:57.0819 5684 srv - ok
11:26:57.0850 5684 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\windows\system32\DRIVERS\srv2.sys
11:26:57.0850 5684 srv2 - ok
11:26:57.0881 5684 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
11:26:57.0881 5684 srvnet - ok
11:26:57.0897 5684 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
11:26:57.0912 5684 SSDPSRV - ok
11:26:57.0944 5684 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\windows\system32\sstpsvc.dll
11:26:57.0959 5684 SstpSvc - ok
11:26:57.0975 5684 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\windows\system32\DRIVERS\stexstor.sys
11:26:57.0975 5684 stexstor - ok
11:26:58.0037 5684 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\windows\System32\wiaservc.dll
11:26:58.0053 5684 StiSvc - ok
11:26:58.0100 5684 [ FF5EB78AF7DFB68C2FB363537AAF753E ] stllssvr c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
11:26:58.0100 5684 stllssvr - ok
11:26:58.0146 5684 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\windows\system32\drivers\swenum.sys
11:26:58.0146 5684 swenum - ok
11:26:58.0178 5684 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\windows\System32\swprv.dll
11:26:58.0193 5684 swprv - ok
11:26:58.0256 5684 [ 1DE40024679CDE0E573465253519730E ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
11:26:58.0256 5684 SynTP - ok
11:26:58.0334 5684 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\windows\system32\sysmain.dll
11:26:58.0365 5684 SysMain - ok
11:26:58.0412 5684 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\windows\System32\TabSvc.dll
11:26:58.0427 5684 TabletInputService - ok
11:26:58.0458 5684 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\windows\System32\tapisrv.dll
11:26:58.0474 5684 TapiSrv - ok
11:26:58.0521 5684 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\windows\System32\tbssvc.dll
11:26:58.0536 5684 TBS - ok
11:26:58.0630 5684 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\windows\system32\drivers\tcpip.sys
11:26:58.0646 5684 Tcpip - ok
11:26:58.0708 5684 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
11:26:58.0724 5684 TCPIP6 - ok
11:26:58.0770 5684 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
11:26:58.0770 5684 tcpipreg - ok
11:26:58.0817 5684 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
11:26:58.0833 5684 TDPIPE - ok
11:26:58.0864 5684 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
11:26:58.0864 5684 TDTCP - ok
11:26:58.0911 5684 [ B459575348C20E8121D6039DA063C704 ] tdx C:\windows\system32\DRIVERS\tdx.sys
11:26:58.0911 5684 tdx - ok
11:26:58.0942 5684 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\windows\system32\drivers\termdd.sys
11:26:58.0942 5684 TermDD - ok
11:26:58.0989 5684 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\windows\System32\termsrv.dll
11:26:59.0020 5684 TermService - ok
11:26:59.0051 5684 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\windows\system32\themeservice.dll
11:26:59.0067 5684 Themes - ok
11:26:59.0082 5684 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\windows\system32\mmcss.dll
11:26:59.0082 5684 THREADORDER - ok
11:26:59.0145 5684 [ 5AD05191DC8B444A7BA4D79B76C42A30 ] TPM C:\windows\system32\drivers\tpm.sys
11:26:59.0145 5684 TPM - ok
11:26:59.0207 5684 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\windows\System32\trkwks.dll
11:26:59.0223 5684 TrkWks - ok
11:26:59.0254 5684 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
11:26:59.0270 5684 TrustedInstaller - ok
11:26:59.0316 5684 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
11:26:59.0316 5684 tssecsrv - ok
11:26:59.0379 5684 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
11:26:59.0379 5684 TsUsbFlt - ok
11:26:59.0426 5684 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
11:26:59.0441 5684 tunnel - ok
11:26:59.0457 5684 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\windows\system32\DRIVERS\uagp35.sys
11:26:59.0457 5684 uagp35 - ok
11:26:59.0504 5684 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\windows\system32\DRIVERS\udfs.sys
11:26:59.0504 5684 udfs - ok
11:26:59.0550 5684 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\windows\system32\UI0Detect.exe
11:26:59.0566 5684 UI0Detect - ok
11:26:59.0628 5684 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
11:26:59.0644 5684 uliagpkx - ok
11:26:59.0691 5684 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\windows\system32\drivers\umbus.sys
11:26:59.0691 5684 umbus - ok
11:26:59.0706 5684 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\windows\system32\DRIVERS\umpass.sys
11:26:59.0706 5684 UmPass - ok
11:26:59.0738 5684 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\windows\System32\upnphost.dll
11:26:59.0753 5684 upnphost - ok
11:26:59.0831 5684 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\windows\system32\DRIVERS\usbser_lowerflt.sys
11:26:59.0831 5684 upperdev - ok
11:26:59.0862 5684 [ 71D97F1A3CC47A56728F7A400A3F8295 ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
11:26:59.0878 5684 usbccgp - ok
11:26:59.0940 5684 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\windows\system32\drivers\usbcir.sys
11:26:59.0940 5684 usbcir - ok
11:26:59.0972 5684 [ C4FB8E7ADEA9B5CEEA885A1B504B7E40 ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
11:26:59.0972 5684 usbehci - ok
11:27:00.0003 5684 [ 86AA95ACB611001E26CD2C0145F2225A ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
11:27:00.0018 5684 usbhub - ok
11:27:00.0034 5684 [ DCDF9855145A14DFCA0AB32308871961 ] usbohci C:\windows\system32\drivers\usbohci.sys
11:27:00.0034 5684 usbohci - ok
11:27:00.0065 5684 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
11:27:00.0081 5684 usbprint - ok
11:27:00.0143 5684 [ 007C0C8D5B01D82ACEB70431D15083F6 ] usbser C:\windows\system32\drivers\usbser.sys
11:27:00.0143 5684 usbser - ok
11:27:00.0206 5684 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\windows\system32\DRIVERS\usbser_lowerfltj.sys
11:27:00.0206 5684 UsbserFilt - ok
11:27:00.0237 5684 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
11:27:00.0237 5684 USBSTOR - ok
11:27:00.0252 5684 [ 8E51D04175BAA14C4F79AA5F6D248770 ] usbuhci C:\windows\system32\DRIVERS\usbuhci.sys
11:27:00.0268 5684 usbuhci - ok
11:27:00.0284 5684 [ DE014425522610BEDCA3821BB8C0F1D5 ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
11:27:00.0284 5684 usbvideo - ok
11:27:00.0315 5684 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\windows\System32\uxsms.dll
11:27:00.0330 5684 UxSms - ok
11:27:00.0362 5684 [ 803B370865D907EA21DC0C2B6A8936B5 ] VaultSvc C:\windows\system32\lsass.exe
11:27:00.0377 5684 VaultSvc - ok
11:27:00.0408 5684 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
11:27:00.0424 5684 vdrvroot - ok
11:27:00.0471 5684 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\windows\System32\vds.exe
11:27:00.0502 5684 vds - ok
11:27:00.0533 5684 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
11:27:00.0533 5684 vga - ok
11:27:00.0549 5684 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\windows\System32\drivers\vga.sys
11:27:00.0564 5684 VgaSave - ok
11:27:00.0596 5684 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
11:27:00.0611 5684 vhdmp - ok
11:27:00.0658 5684 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\windows\system32\drivers\viaagp.sys
11:27:00.0658 5684 viaagp - ok
11:27:00.0674 5684 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\windows\system32\DRIVERS\viac7.sys
11:27:00.0689 5684 ViaC7 - ok
11:27:00.0720 5684 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\windows\system32\drivers\viaide.sys
11:27:00.0720 5684 viaide - ok
11:27:00.0752 5684 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\windows\system32\drivers\volmgr.sys
11:27:00.0752 5684 volmgr - ok
11:27:00.0783 5684 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
11:27:00.0798 5684 volmgrx - ok
11:27:00.0830 5684 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\windows\system32\drivers\volsnap.sys
11:27:00.0830 5684 volsnap - ok
11:27:00.0876 5684 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\windows\system32\DRIVERS\vsmraid.sys
11:27:00.0892 5684 vsmraid - ok
11:27:00.0954 5684 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\windows\system32\vssvc.exe
11:27:01.0001 5684 VSS - ok
11:27:01.0032 5684 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
11:27:01.0032 5684 vwifibus - ok
11:27:01.0048 5684 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
11:27:01.0048 5684 vwififlt - ok
11:27:01.0095 5684 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
11:27:01.0095 5684 vwifimp - ok
11:27:01.0142 5684 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\windows\system32\w32time.dll
11:27:01.0157 5684 W32Time - ok
11:27:01.0204 5684 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\windows\system32\DRIVERS\wacompen.sys
11:27:01.0204 5684 WacomPen - ok
11:27:01.0251 5684 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
11:27:01.0266 5684 WANARP - ok
11:27:01.0266 5684 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
11:27:01.0282 5684 Wanarpv6 - ok
11:27:01.0391 5684 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
11:27:01.0422 5684 WatAdminSvc - ok
11:27:01.0485 5684 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\windows\system32\wbengine.exe
11:27:01.0516 5684 wbengine - ok
11:27:01.0563 5684 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
11:27:01.0578 5684 WbioSrvc - ok
11:27:01.0641 5684 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\windows\System32\wcncsvc.dll
11:27:01.0656 5684 wcncsvc - ok
11:27:01.0672 5684 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
11:27:01.0688 5684 WcsPlugInService - ok
11:27:01.0734 5684 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\windows\system32\DRIVERS\wd.sys
11:27:01.0734 5684 Wd - ok
11:27:01.0797 5684 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
11:27:01.0797 5684 Wdf01000 - ok
11:27:01.0828 5684 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\windows\system32\wdi.dll
11:27:01.0844 5684 WdiServiceHost - ok
11:27:01.0859 5684 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\windows\system32\wdi.dll
11:27:01.0875 5684 WdiSystemHost - ok
11:27:01.0922 5684 [ 75E8EBD7040CE238684333F97014762A ] WebClient C:\windows\System32\webclnt.dll
11:27:01.0937 5684 WebClient - ok
11:27:01.0968 5684 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\windows\system32\wecsvc.dll
11:27:01.0984 5684 Wecsvc - ok
11:27:02.0000 5684 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\windows\System32\wercplsupport.dll
11:27:02.0015 5684 wercplsupport - ok
11:27:02.0062 5684 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\windows\System32\WerSvc.dll
11:27:02.0078 5684 WerSvc - ok
11:27:02.0140 5684 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
11:27:02.0140 5684 WfpLwf - ok
11:27:02.0171 5684 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\windows\system32\drivers\wimmount.sys
11:27:02.0171 5684 WIMMount - ok
11:27:02.0249 5684 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:27:02.0249 5684 WinDefend - ok
11:27:02.0296 5684 WinHttpAutoProxySvc - ok
11:27:02.0358 5684 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
11:27:02.0374 5684 Winmgmt - ok
11:27:02.0436 5684 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\windows\system32\WsmSvc.dll
11:27:02.0483 5684 WinRM - ok
11:27:02.0561 5684 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
11:27:02.0577 5684 WinUsb - ok
11:27:02.0624 5684 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\windows\System32\wlansvc.dll
11:27:02.0655 5684 Wlansvc - ok
11:27:02.0717 5684 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys
11:27:02.0717 5684 WmiAcpi - ok
11:27:02.0748 5684 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
11:27:02.0764 5684 wmiApSrv - ok
11:27:02.0873 5684 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:27:02.0889 5684 WMPNetworkSvc - ok
11:27:02.0920 5684 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\windows\System32\wpcsvc.dll
11:27:02.0936 5684 WPCSvc - ok
11:27:02.0951 5684 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
11:27:02.0967 5684 WPDBusEnum - ok
11:27:02.0998 5684 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
11:27:02.0998 5684 ws2ifsl - ok
11:27:03.0029 5684 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\windows\System32\wscsvc.dll
11:27:03.0045 5684 wscsvc - ok
11:27:03.0060 5684 WSearch - ok
11:27:03.0170 5684 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\windows\system32\wuaueng.dll
11:27:03.0232 5684 wuauserv - ok
11:27:03.0279 5684 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
11:27:03.0279 5684 WudfPf - ok
11:27:03.0326 5684 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
11:27:03.0341 5684 WUDFRd - ok
11:27:03.0388 5684 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\windows\System32\WUDFSvc.dll
11:27:03.0404 5684 wudfsvc - ok
11:27:03.0450 5684 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\windows\System32\wwansvc.dll
11:27:03.0466 5684 WwanSvc - ok
11:27:03.0575 5684 [ F0CEEA6CC0E5BFEFC745B66DC5E9816B ] yksvc C:\windows\System32\yk62x86.dll
11:27:03.0591 5684 yksvc - ok
11:27:03.0653 5684 [ 3EB1576F77B60A6C79DD7742B67219B8 ] yukonw7 C:\windows\system32\DRIVERS\yk62x86.sys
11:27:03.0669 5684 yukonw7 - ok
11:27:03.0700 5684 ================ Scan global ===============================
11:27:03.0731 5684 [ DAB748AE0439955ED2FA22357533DDDB ] C:\windows\system32\basesrv.dll
11:27:03.0762 5684 [ 51BB04243DF6196C06E125898127E397 ] C:\windows\system32\winsrv.dll
11:27:03.0794 5684 [ 51BB04243DF6196C06E125898127E397 ] C:\windows\system32\winsrv.dll
11:27:03.0825 5684 [ 364455805E64882844EE9ACB72522830 ] C:\windows\system32\sxssrv.dll
11:27:03.0856 5684 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\windows\system32\services.exe
11:27:03.0872 5684 [Global] - ok
11:27:03.0887 5684 ================ Scan MBR ==================================
11:27:03.0887 5684 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
11:27:04.0262 5684 \Device\Harddisk0\DR0 - ok
11:27:04.0262 5684 ================ Scan VBR ==================================
11:27:04.0262 5684 [ 71A91550D1265D8A13C3BE3A9D3EE537 ] \Device\Harddisk0\DR0\Partition1
11:27:04.0262 5684 \Device\Harddisk0\DR0\Partition1 - ok
11:27:04.0293 5684 [ 32AE69FD2FD6A4DD720EDEBCF7A84CD5 ] \Device\Harddisk0\DR0\Partition2
11:27:04.0293 5684 \Device\Harddisk0\DR0\Partition2 - ok
11:27:04.0324 5684 [ 84985B662BB1C124854CFF929A0DB9FB ] \Device\Harddisk0\DR0\Partition3
11:27:04.0324 5684 \Device\Harddisk0\DR0\Partition3 - ok
11:27:04.0340 5684 [ 29785AAED9AC60153D823B174F12434E ] \Device\Harddisk0\DR0\Partition4
11:27:04.0340 5684 \Device\Harddisk0\DR0\Partition4 - ok
11:27:04.0340 5684 ============================================================
11:27:04.0340 5684 Scan finished
11:27:04.0340 5684 ============================================================
11:27:04.0371 4280 Detected object count: 1
11:27:04.0371 4280 Actual detected object count: 1
11:27:41.0982 4280 SafeBoot ( LockedFile.Multi.Generic ) - skipped by user
11:27:41.0982 4280 SafeBoot ( LockedFile.Multi.Generic ) - User select action: Skip
11:27:58.0456 2888 Deinitialize success

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 17 lis 2013 19:55

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Holecek
Level 2.5
Level 2.5
Příspěvky: 328
Registrován: červen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Holecek » 17 lis 2013 21:41

ComboFix 13-11-16.01 - KATKA 17.11.2013 21:14:33.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3000.2041 [GMT 1:00]
Spuštěný z: c:\users\KATKA\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-17 do 2013-11-17 )))))))))))))))))))))))))))))))
.
.
2013-11-16 12:16 . 2013-11-17 09:44 -------- d-----w- c:\users\KATKA\AppData\Local\CrashDumps
2013-11-16 12:01 . 2013-11-16 12:01 -------- d-----w- c:\windows\ERUNT
2013-11-15 21:47 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B5004EC9-0576-457A-B688-7F26E3B33099}\mpengine.dll
2013-11-15 21:42 . 2013-11-15 21:42 -------- d-----w- c:\users\KATKA\AppData\Local\AOL
2013-11-15 21:33 . 2013-11-15 21:33 -------- d-----w- c:\users\KATKA\AppData\Local\Adobe
2013-11-15 21:16 . 2013-11-16 11:54 -------- d-----w- C:\AdwCleaner
2013-11-15 20:25 . 2013-11-15 20:25 -------- d-----w- c:\users\KATKA\AppData\Roaming\Apple Computer
2013-11-15 20:11 . 2013-11-15 20:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-11-15 20:11 . 2013-11-15 20:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-11-15 20:11 . 2013-11-15 20:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-11-15 20:11 . 2013-11-15 20:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-11-15 20:11 . 2013-11-15 20:11 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-11-15 20:10 . 2013-11-15 20:11 -------- d-----w- c:\program files\QuickTime
2013-11-15 20:10 . 2013-11-15 20:10 -------- d-----w- c:\programdata\Apple Computer
2013-11-15 20:09 . 2013-11-15 20:09 -------- d-----w- c:\program files\Common Files\Apple
2013-11-15 20:08 . 2013-11-15 20:08 -------- d-----w- c:\program files\Apple Software Update
2013-11-15 20:08 . 2013-11-15 20:08 -------- d-----w- c:\programdata\Apple
2013-11-15 19:41 . 2013-11-15 19:41 -------- d-----w- c:\users\KATKA\AppData\Roaming\Geek Uninstaller
2013-11-15 19:30 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-15 19:30 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-15 19:30 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-15 19:30 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-15 19:30 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-15 19:30 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-15 19:30 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-11-15 17:58 . 2013-11-15 17:58 20 --sha-w- c:\users\KATKA\AppData\Roaming\App4870.ConfCollection.bin
2013-11-15 17:58 . 2013-11-15 17:58 0 ----a-w- c:\users\KATKA\AppData\Local\jv16PT_temp.tmp
2013-11-15 17:58 . 2013-11-15 17:58 -------- d-----w- c:\program files\PowerTools Lite 2013
2013-11-15 17:31 . 2013-11-15 17:32 -------- d-----w- c:\program files\Temp
2013-11-14 19:05 . 2013-10-04 01:58 152576 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-11-14 19:04 . 2013-10-05 19:57 1168384 ----a-w- c:\windows\system32\crypt32.dll
2013-11-14 19:04 . 2013-10-12 02:01 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-11-14 19:04 . 2013-10-12 02:03 656896 ----a-w- c:\windows\system32\nshwfp.dll
2013-11-14 19:04 . 2013-10-12 02:01 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-11-02 20:32 . 2013-11-02 20:32 -------- d-----w- c:\program files\Microsoft Silverlight
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-15 19:57 . 2012-04-20 14:19 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-11-15 19:57 . 2011-05-23 15:52 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-25 01:57 . 2013-11-14 19:05 247808 ----a-w- c:\windows\system32\schannel.dll
2013-09-14 00:48 . 2013-10-11 04:22 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-08 02:07 . 2013-10-11 04:22 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:03 . 2013-10-11 04:22 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-09-03 12:35 . 2010-08-29 09:33 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-08-30 07:48 . 2013-03-18 17:46 177864 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2009-12-28 17:58 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2009-12-28 17:58 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2013-03-18 17:46 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2012-03-01 16:05 61680 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2011-02-23 18:43 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2009-12-28 17:58 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2009-12-28 17:57 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2010-08-29 08:22 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2009-12-28 17:57 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-29 01:51 . 2013-10-11 04:22 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-29 01:51 . 2013-10-11 04:22 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-29 01:50 . 2013-10-11 04:22 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-29 01:50 . 2013-10-11 04:22 619520 ----a-w- c:\windows\system32\tdh.dll
2013-08-29 01:48 . 2013-10-11 04:22 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-08-29 01:12 . 2013-10-11 04:22 28160 ----a-w- c:\windows\system32\drivers\usbser.sys
2013-08-28 01:04 . 2013-10-11 04:21 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-08-28 00:57 . 2013-10-11 04:21 434688 ----a-w- c:\windows\system32\scavengeui.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 121968 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-25 186904]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-08-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-08-02 174104]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2013-08-30 4858968]
.
c:\users\KATKA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-30 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\HEWLET~1\IAM\Bin\APSHook.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2009-07-16 00:51 1668664 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2009-07-30 45056]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-11-01 137600]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2011-11-01 8576]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-11 1343400]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 SafeBoot;SafeBoot; [x]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 RsvLock;RsvLock; [x]
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
S2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-08-30 66336]
S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [2009-07-29 1201400]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-07-29 256544]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S3 5U876UVC;HP Webcam [2 MP series];c:\windows\system32\DRIVERS\5U876.sys [2009-06-30 13:01 118656]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-25 122368]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-20 313856]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker
Bioscrypt REG_MULTI_SZ ASChannel
yksvcs REG_MULTI_SZ yksvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-21 04:23 1185744 ----a-w- c:\program files\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-20 19:57]
.
2013-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-01 16:09]
.
2013-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-01 16:09]
.
2013-11-12 c:\windows\Tasks\HPCeeScheduleForKATKA.job
- c:\program files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 20:15]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-11-16 13:35; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\KATKA\AppData\Roaming\Mozilla\Firefox\Profiles\phy63bx8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-McAfee Managed Services Tray - c:\program files\McAfee\Managed VirusScan\Agent\StartMyAgtTry.Exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3952)
c:\program files\Hewlett-Packard\IAM\Bin\ItClient.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Hewlett-Packard\IAM\Bin\AsGHost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-11-17 21:39:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-17 20:39
.
Před spuštěním: Volných bajtů: 227 680 542 720
Po spuštění: Volných bajtů: 227 445 207 040
.
- - End Of File - - 545C92A8D026AF756520CB642F49B4DA
5C616939100B85E558DA92B899A0FC36

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 18 lis 2013 10:10

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

File::
c:\users\KATKA\AppData\Local\jv16PT_temp.tmp
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\program files\Skype\Updater
c:\program files\Google\Update

Driver::
SkypeUpdate

DDS::
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.

Avast5--zaktualizuj si program na Avast8.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 97 hostů